Fingerprints are the worst possible method for authentication. If a digital fingerprint is stolen (all are digitized nowadays) unlike a password, you cannot create another fingerprint. It's fixed forever to you. Which is incredibly weak security.

So what are the methods of stealing fingerprints on PC's? are there trojans who steal them? and what could we do with them?

Fingerprint software that detects a pattern in a print must be somewhat fuzzy otherwise authentication fails often. The software might set fixed points and measures it's distance. Hold your finger in a slightly different angle, and it still detects your print. So it must be fuzzy in a sense that it "scores" the points with some algorithm.

So can we bruteforce it?

There 7+ Bn people. Not a really large number in terms of computing. Think about the birthday attack. Could we bruteforce a fingerprint? Let's say we create rainbow table of computer generated fingerprints?

I've cracked my way into a mid-size (~400M) trading firm's data center via biometric thumb scan using a pencil, tape and a copy machine. The first thing out of their security guy's mouth was "you're fuckin fucking me fuck, fuck fuck". It was supposed to be active biometrics, using both the fingerprint and checking for blood flow or heat, I'm not sure which, but it turns out my thumb pushing down on a photocopied imprint of whoever used it last was good enough.

Nothing really more fun in my line of work as when I get to break into physical DCs... I broke into 4 more of the same company's DCs using just a notebook, thought the security dude was going to cry when I tossed it under the door and activated the motion sensor they had unlocking the door from the inside...